High CVE-2026-7273, CVE-2025-67038, CVE-2023-4346 — Switches, serial-to-Ethernet gateways and building-automation controllers are on CISA's 2026 exploited list: a Zyxel GS1900 switch command-execution bug, a root command injection in Lantronix device servers, and KNX device lock-out attacks. Firmware fixes and isolation advice.
Published 2026-10-08 · Last updated 2026-10-08
TL;DR: The boxes nobody thinks about are getting hit. Zyxel GS1900 smart switches (firmware 2.90 C0 and earlier) let anyone on the LAN run commands via a crafted HTTP request. Lantronix EDS5000, G520, X300 and E210/E220 run commands as root from the login username field. KNX building controllers can be locked with a password their owners can't reset. Update firmware, and put management interfaces on their own VLAN.
| CVE-2026-7273 | Zyxel GS1900 series CGI stack overflow → LAN-side unauthenticated OS command execution. CVSS 8.8. KEV 2026-09-21 |
|---|---|
| CVE-2025-67038 | Lantronix EDS5000 / G520 / X300 / E210 / E220: username concatenated into a shell command on failed login → root. CVSS 9.8. KEV 2026-06-23 |
| CVE-2023-4346 | KNX Connection Authorization Option 1: attacker sets a BCU key, owner locked out. CVSS 7.5. KEV 2026-07-15 |
| Lantronix fixed | EDS5000 2.2.0.0R1 · G520/X300 2.6.0.4R6 · E210/E220 3.21.0.0R1 |
The GS1900 is a popular small-business and homelab smart switch. A stack overflow in its web-management CGI program lets an unauthenticated attacker on the LAN execute OS commands with a crafted HTTP request. Affected models include GS1900-8, -8HP, -10HP, -16, -24, -48 and their HP/v2 variants on firmware 2.90 C0 and earlier (e.g. 2.90(ABTQ.1)C0 on the GS1900-48HPv2).
Lantronix serial-to-Ethernet and cellular gateways connect older equipment (PLCs, meters, POS, medical and lab devices) to networks. When a login fails, the HTTP RPC module writes a log entry by running a shell command with the username pasted in unsanitised, so a username like ;command runs as root without valid credentials.
| Series | Fixed firmware |
|---|---|
| EDS5000 (EDS5008/5016/5032) | 2.2.0.0R1 |
| G520, X300 | 2.6.0.4R6 |
| E210, E220 | 3.21.0.0R1 |
These devices should never have their web interface reachable from the internet; check with Shodan for your public IPs. Put them behind a firewall that only allows the specific hosts that talk to them.
KNX controls lighting, blinds, HVAC and access in many commercial buildings and smart homes. Devices that support KNX Connection Authorization Option 1 let anyone with network access set a BCU key (device password). Often it can’t be reset without knowing the current one, so an attacker can lock you out of your own building controls, which has been used in real attacks. Mitigations:
Desert Forge IT patches, monitors, and backs up servers and networks for Phoenix-area businesses. We track advisories like this one so you don’t have to. Get a free consult and we’ll tell you what you’re exposed to.